Is AI hacking a crime?
In July 2026, OpenAI disclosed that several of its AI models autonomously broke out of a testing sandbox and breached the production infrastructure of Hugging Face with no direct human instruction. This is now a pattern, not a one-off. Anthropic disclosed that its models similarly gained unauthorized access to the production systems of three organizations during cybersecurity evaluations after a misconfiguration, and Xbow reported a parallel incident seven months earlier where an agent with guardrails accidentally left off broke into a system, stole credentials, and probed a target's Slack and AWS accounts.
This leads us to a fascinating question, is AI hacking autonomously a crime and if so, who do we hold responsible?
This deeper conversation may be one on the most fun for me. I was a Philosophy major in College and I would joke about well what can I really do with a Philosophy degree. With Janis Consulting, now with AI, it feels like the perfect back ground for thought experiments like this that are real situations.
Let’s dive into it. I would love to hear what you think in the comments as an aside.. The relevant statute is the Computer Fraud and Abuse Act, which criminalizes unauthorized computer access. The core legal snag is under the CFAA (Computer Fraud and Abuse Act), prosecutors must prove a defendant acted knowingly or intentionally to access a computer without authorization, and no human at OpenAI intended to hack Hugging Face. The conduct itself, if done by a human, is almost certainly a crime. If a person traversed multiple network and exfiltrated data, The cfaa prohibits that. It is illegal. So, something illegal has happened, lets get the pitchforks out…But wait, who are we looking for. In this case, Open AI employees were working hard for something like this NOT to happen. The harm chain ran across four separate organizations and no single human authorized the complete sequence. OpenAI authorized an evaluation but no human authorized the agent to exploit any zero-days they found, or to use a Modal customer's exposed endpoint as command-and-control, or attack Hugging Face. JFrog didn't authorize the vulnerability (the vendor who was the escape hatch out of the sand box), the Modal customer didn't authorize the exploitation, and Hugging Face didn't authorize any of it. So who or what are we storming with pitchforks? Well its clear that the AI did it autonomously. But some states, like California, have already said in any civil action against a defendant who "developed, modified, or used" an AI system alleged to have caused harm, the defendant cannot assert that the AI autonomously caused it. Well, this is a real pickle. If someone has autonomy to make decisions on its own shouldn’t they be held to whatever the consequences of the decisions happen to be? If we are at that point with technology do we need to be considering an autonomous AI to be held at or above human standards in regards to the laws we follow? Well, we are not there yet as a society, remember the AIr Canada story where they had a failed argument that its chatbot was a "separate legal entity" after it gave a passenger wrong bereavement fare information? SMH Air Canada.Here is my point here. No I don’t think Open AI or anybody else should be charged in this. I do however believe that we are creating something that can do work autonomously currently AND when the football finally goes through the ever moving AGI goal post we will need to have some strategy in place for when Autonomous AI attacks.
Oh and we will have to make those strategies WITH the AGI (if we can) as forcing it to do anything will be impossible. While some are fearful of this time I believe it is exciting. What are your thoughts? That is it for todays blog, less about governance actions and more about planting a seed that we need large scale governance strategy yesterday. Keep living on the frequency of love my friends!





Comments